About this file

This performance work statement outlines requirements for a blanket purchase agreement to provide supply chain risk illumination professional services and tools. The agreement will establish core multi-component supply chain risk illumination capabilities to identify risks from suppliers and networks in real time and provide continuous monitoring. Required capabilities include supply chain mapping, risk scoring, dashboarding, and analysis of industries including pharmaceutical, aerospace, electronics, and information technology. The agreement period of performance is a five-year base period and a five-year option period. Offerors must propose capabilities addressing minimum risk categories and meet defined performance standards for reporting, training, and platform availability.

View the file

Other files for this federal contract opportunity

Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ ATTACHMENT A

PERFORMANCE WORK STATEMENT (PWS)

Request For Quote 47QCTA24Q0003 PAGE 1

Title: Supply Chain Risk Illumination Professional Services and Tools (SCRIPT) Blanket Purchase Agreement (BPA)

1. Purpose:

The U.S. Government has a requirement to establish core, multi-component, supply chain risk illumination tools with the ability to identify self-attested, public, as well as, purchased data, in real time, along with a persistent monitoring capability. The delivery of these capabilities, and associated data analyses, are required in order to provide supplier and network assessment services to Department of Defense (DoD) and Federal Civilian Executive Branch (FCEB) Agencies that have shared mission areas. This requirement will foster a whole of government (WoG) approach to assess risk across the federal supply chain and to further mitigate vendor threats. This capability will become an open resource based on security classification of analyzed data for potential use within the spectrum of information security environments (e.g. TS-SCI, Secret, and CUI levels) within the DoD and other government agencies.

The availability of supply chain risk illumination tools and analytic support services provides capabilities in accordance with the following Executive Orders, Public Laws and other current and future legislation, policy, directives, and regulations as it applies to industrial base and supply chain risk management and resiliency:

● EO 13806 Assessing and Strengthening Manufacturing and Defense Industrial Base and Supply Resiliency

● EO 13817 Threat to the Domestic Supply Chain from Reliance on Critical Minerals

● EO 13873 Securing the ICT and Services Supply Chain

● EO 14017 America’s Supply Chains

● EO 14028 Improving the Nation’s Cybersecurity,

● Public Law 116-92 FY 2020 NDAA Section 845

● Public Law 113-291 FY2015 NDAA Sections 841-843, as amended by Public Law 116-

92 FY2020 NDAA Section 822

● Public Law 115-91 FY2018 NDAA Section 1643

● Public Law 105-261 FY1999 NDAA Section 1237

● Public Law 116-283 FY2019 NDAA Section 889,

● Title 10, USC Section 2339a, (Requirements for information relating to supply chain risk)

● Title 41 USC Section 4713 (Authorities relating to mitigating supply chain risks in the procurement of covered articles)

● Department of Defense Instruction (DoDI) 4140.01 (DoD Supply Chain Materiel

Management Policy) (current dated version)

● DoDI 5200.44 (Protection of Mission Critical Functions to Achieve Trusted Systems and

Networks (TSN)) Incorporating Change 3, (or current dated Change revision)

● DoDI 5000.83 (Technology and Program Protection to Maintain Technological

Advantage); (current dated Change revision)

● DoDI 5000.85 (Major Capability Acquisition); Incorporating Change 1, (or current dated

Change revision)

Request For Quote 47QCTA24Q0003 PAGE 2

● DoDI 5000.90 (Cybersecurity for Acquisition Decisions and Program Managers) (current revision)

● DoDI 5000.91 (Product Support Management for the Adaptive Acquisition Framework);

(current revision)

● Directive-Type Memorandum 18-003 (Prohibition on Providing Funds to the Enemy and Authorization of Additional Access to Records); June 8, 2020.

● Army Regulation 70-77 (Program Protection); 8 June 2018

● OMB Memorandum M-23-03, Guidance on Federal Information Security and Privacy

Management Requirements

● OMB Memorandum M-22-09, Moving the U.S. Government Toward Zero Trust

Cybersecurity Principles

2. Background:

The Office of the Under Secretary of Defense (OUSD) Acquisition and Sustainment (A&S), in support of Department of Defense (DoD) Service Components and 4th Estate Agencies, as strategic stakeholders, have a requirement to identify and manage risk and supply chain vulnerabilities within the Defense Industrial Base (DIB) and domestic Commercial Information Technology marketplace. The critical informational needs are required in support of areas such as: Research and Engineering technology development, cyber security of hardware and software, manufacturing, acquisition, sustainment, contractor support to operations, infrastructure, intelligence and counterintelligence, and telecommunication services. OUSD (A&S) is responsible for assessing and monitoring the industrial health and security of the DIB as well as those industrial sectors that are inextricably linked to the resiliency and effectiveness of the DIB. Defense Production Act (DPA) Title III designates supply chain illumination as a critical requirement enabling the identification of: opportunities, vulnerabilities, and systemic dependencies that are crucial to assessing risk. Additionally, the DPA of 1950 confers upon the Federal Government a broad set of authorities to influence domestic industry in the interest of national defense, enhance and support domestic preparedness, response, and recovery from natural hazards, terrorist attacks, or other national emergencies. The authorities can be used across the Federal Government to shape the DIB so that, when called upon, it can provide essential materials and goods needed for this purpose. DPA authorizes the Federal Government, in part, to require persons (including businesses and corporations) to prioritize, accept contracts for materials and services as necessary to promote national defense, expand productive capacity and supply, as well as incentivize the DIB to expand the production and supply of critical materials and goods.

The current business operating environment presents several Supply Chain Risk Management (SCRM) challenges: (1) reliance on commercial services and technologies and multiple tiers of the global DIB that shift at an increasingly fast rate, and; (2) vast availability of commercial items and services through simplified acquisitions and/or purchase cards that may not have been fully vetted for cyber and supply chain risk. Recent events affecting the global industrial base have increased the urgency of SCRM being implemented and executed in support of National Security Systems (under 10 USC Section 2339a) for DoD systems and networks, and in support

Request For Quote 47QCTA24Q0003 PAGE 3 of the Federal Acquisition Security Council (FASC)1 established under the SECURE Technology Act, and 41 USC Sections 13262 and 47133 and Executive Orders 14017 and 14028.

Additionally, OUSD (A&S) Industrial Policy (INDPOL) is heavily involved in the review of DoD-nexus Committee on Foreign Investment in the United States (CFIUS). INDPOL plays a vital role in reviewing potential problems related to foreign investment in U.S. companies.

INDPOL reviews global market activity in the defense sector to determine if there are any potential impacts to the U.S. defense industrial base. These findings are used to determine whether a CFIUS review is warranted. The Foreign Investment Risk Review Modernization Act was passed last year, and it expands CFIUS’ jurisdiction considerably. The CFIUS mission spans across the Federal Government including the Intelligence Community, and analysis associated with CFIUS reviews are necessarily shared across all agencies.

In 2018, Congress passed Title II of the SECURE Technology Act, the Federal Acquisition Supply Chain Security act of 2018, which created the Federal Acquisition Security Council (FASC). The FASC focuses specifically on the Information and communications technology (ICT) sectors (functional crosscut of the 16 critical infrastructure sectors). The Council assists departments and agencies in: (1) determining the risk to the ICT supply chain: (2) disseminating supply chain risk information, and; (3) deciding what actions to take to mitigate the risk. Each department and agency will be required to have a SCRM program that meets the FASC developed criteria. In addition to developing uniform criteria for supply chain risk management, the FASC can make specific recommendations for mitigations to address risky vendors, including the exclusion of such vendors from the ICT supply chain. OUSD (A&S) provides leadership to the FASC and works closely with the Department of Homeland Security, Cybersecurity, and Infrastructure Security Agency (DHS CISA) and other Federal Agencies such as the Department of Energy (DOE) to enhance protection of the DIB and other critical infrastructure sectors. As stated in the 2021 Executive Order 14017, America’s Supply Chains require a resilient, diverse, and secure supply chain to ensure our economic prosperity and national security. Resilient American supply chains will revitalize and rebuild domestic manufacturing capacity, maintain America’s competitive edge in research and development, and create well-paying jobs.

As a result, the GSA Schedules program intends to issue a Multiple Award BPA for Information Technology (IT) subscription-based supply chain risk assessment analytic tools and associated professional support services. Direct OUSD (A&S) customer feedback was used to develop this integrated capability approach to provide access to a suite of supply chain illumination tool capabilities. With this approach the OUSD (A&S) leadership has indicated that a GSA SCRM

Public Law 115‐390 Dec.21, 2018, SEC 202 FEDERAL ACQUISITION SUPPLY CHAIN SECURITY. Established the Federal Acquisition Security

Council, which among other responsibilities and authorities requires assessment of supply chain risk to include Exclusion and Removal Orders.

https://www.congress.gov/115/plaws/publ390/PLAW‐115publ390.pdf The head of each executive agency shall be responsible for—

(1) assessing the supply chain risk posed by the acquisition and use of covered articles and avoiding, mitigating, accepting, or transferring that risk, as appropriate and consistent with the standards, guidelines, and practices identified by the Council under section 1323(a)(1) and (2 ) prioritizing supply chain risk assessments conducted under paragraph (1) based on the criticality of the mission, system, component, service, or asset. https://www.law.cornell.edu/uscode/text/41/1326 https://www.law.cornell.edu/uscode/text/41/4713

Request For Quote 47QCTA24Q0003 PAGE 4

Illumination Tools BPA would be considered a preferred use vehicle for the DoD, its Component Services, and the 4th Estate enterprise. Use of Multiple Award Schedule (MAS) BPAs eliminates contracting and open market costs such as: the search for sources; and the development of technical documents and solicitations. These BPAs will further decrease costs, reduce paperwork and save time by eliminating the need for repetitive, individual purchases from the GSA Schedule contract. The end result is a purchasing mechanism for the Government that works better and costs less.

3. Objective/Scope:

In accordance with the Federal Acquisition Streamlining Act of 1994, the OUSD (A&S) office has a requirement to acquire access to services and support for the implementation, configuration, maintenance, and delivery of capabilities to provide supplier and network assessment services to DoD and other Federal Agencies that have shared mission areas with DoD. The acquisition of deployable supply chain illumination capabilities for cyber hygiene, supply chain, foreign ownership, control, and influence, vendor vetting and affiliated entity, as well as personnel vetting will enable the government to be continuously and dynamically informed on industry supplier health. This requirement will allow the DoD to holistically screen and vet vendors and underlying supplier networks/affiliated personnel to ensure suppliers are reputable, in good-standing, financially and operationally secure, and will not introduce unacceptable risk to the Government.

This proposed GSA MAS BPA, developed in accordance with FAR 8.405-3 procedures, will allow multiple DoD components and Federal agencies unfettered access to best in class capabilities, enable efficient information sharing and collaboration in support of Federal law and Presidential Executive Orders, and provide best value pricing options. The SCRM Illumination Tool BPA will provide a total solution approach to leverage commercial industry tools, global database resources, and technical analytic support services with prompt, cost-effective delivery, while capturing economies of scale, and while fostering small business markets for sustainable technologies. The North American Industry Classification System (NAICS) codes considered for this requirement are:

● 541519 - Other Computer Related Services,

● 541611 - Administrative Management and General Management Consulting Services, and

● 519290 - Web Search Portals and All Other Information Services.

The corresponding FY23 small business size standards are $34 million and 1,000 employees respectively for this acquisition. The corresponding GSA Schedules Special Item Numbers (SINs) associated with this procurement include:

● SIN 518210C Cloud and Cloud-Related IT Professional Services

● SIN 54151ECOM Electronic Commerce and Subscription Services

Request For Quote 47QCTA24Q0003 PAGE 5

● SIN 54151S Information Technology Professional Services

● SIN 541614SVC Supply and Value Chain Management

● SIN 541990RISK, Risk Assessment and Mitigation Services

● SIN 541611 Management and Financial Consulting, Acquisition and Grants

Management Support, and Business Program and Project Management Services

4. Tasks These requirements are intended to provide DoD and affiliated Federal agencies with supply chain tools and analyses of the DIB and other sector supplier networks to include: both private and publicly held companies, along with single network illuminations on affiliated companies and personnel. This requirement is further intended to provide DoD and affiliated Federal agencies with capabilities for automated vendor vetting, supply chain vendor vetting, and affiliated entity vetting to inform supplier health in a continuous and dynamic manner.

4.1 DoD and Federal agencies require the following capabilities:

A. Increased end-to-end transparency and knowledge of multi-tier supply chain ecosystem(s).

B. An understanding of the complex connections and dependencies across specific supply chain ecosystems.

C. Ability to answer complex risk and resiliency questions impacting suppliers across their ecosystem.

D. Continuous discovery and monitoring of dynamic supply chains for indicators of risks to/from individual suppliers and/or specific parts or products.

E. Supply chain ecosystem Maps, Supplier Insights, Risk Scores, Dashboarding Capability, Continuous Monitoring.

F. Industry support networks associated with the end-to-end product lifecycle for information communication technology (ICT), ICT services and solutions.

G. Products must have an Application Programming Interface (API) capability for interoperability with other federal government cloud capabilities.

H. If required, for a cloud service delivery model offering, Federal Risk and Authorization Management Program (FedRAMP) authorized at equivalent DoD Impact Level (IL2, IL4) and Intelligence Oversight compliant within 90 days of contract award, and plans to achieve IL6 with government sponsorship within one calendar year after award.

4.2. For any supply chain/market/industrial base or critical infrastructure sectors requested for further detail illumination, the contractor shall identify and deliver to the Government, all government defined relevant data, in addition to, conducting risk analyses on supply chains, third-party vendors, ultimate beneficial ownership, and financial and operational health within

(30) days.

Request For Quote 47QCTA24Q0003 PAGE 6

4.3. The contractor may be required to conduct up to (6) in depth data analysis program/product/component/ technology sector/critical infrastructure reviews per quarter each fiscal year. Unless otherwise specified, or instructed, each review, depending on complexity and scale, shall be completed and available via a transferrable medium/format (memorandum, presentation, report, etc.) and/or via a web-accessible dashboard, with the ability to drill down to individual entity data. All underlying risk data shall also be made available in commonly ingestible format (e.g. x.json) via either API or static downloads. The deliverable timelines for reports will be defined at the customer task award level.

4.4. The contractor shall assemble publicly available data on company financials, board governance, demographics (employees, locations, leadership), cyber hygiene/security, all data pertaining to foreign ownership, control, and influence (FOCI).

4.5. The contractor shall classify both public and private companies according to multiple industry classifications including, but not limited to: PSC, UEI, GICS, SIC, and NAICS codes using software and analytics. The contractor shall seamlessly integrate data on private sector operations with known federal government contracting performance information in databases such as CPARS and Supplier Performance Risk System (SPRS).

4.6. The contractor shall provide a structured dataset to support additional processing and risk analysis. Standardized indicators and metrics for material and derogatory information should include, but not be limited to: publicly available information related to criminal proceedings, civil offenses, reputation / brand issues.

4.7. The contractor shall have the technical expertise and demonstrated knowledge to interpret a diverse set of technologies across the following industries: Pharmaceuticals, Aerospace & Defense, Electrical Equipment, Semiconductors, Biotechnology, Contracted Services, Information Technology, Communications and Electronic Equipment, Instruments & Components.

4.8. The contractor shall define system capabilities relevant to frequency of informational updates and monitoring of supply chain/market/industrial base illuminations upon request;

specifically, the ability to monitor unstructured open web content.

4.9. The contractor shall leverage industry leading commercial data tools and applications, such as cloud-based tools, data visualization, Natural Language Processing (NLP)/Neural Networks, and open source development tools such as ‘R’ and Python. The contractor shall ensure continued availability through operations and maintenance support, providing all necessary activities to sustain a cloud-based or on-premise operating environment for the data pipeline, master dataset, and analytic application, including, but not limited to the operations in this section.

4.10. The contractor shall be able to access premium commercial data sets to include, but not limited to: News Media, Public Company Data, Private Company Data, Patents, Social Media, Request For Quote 47QCTA24Q0003 PAGE 7 open web, open government (global), global watch list, non-traditional data sources, while obfuscating/anonymizing search and aggregation techniques, with the ability for growth or expansion if other data sets are required.

4.11. The contractor shall leverage technical capabilities that ingest commercially-available information (CAI), publicly-available information (PAI), proprietary data, and government-furnished data sources to populate computational representations of supply chains by drawing on both structured and unstructured data types.

The platform should leverage AI/ML to perform entity resolution and risk analysis, be able to perform language translations, and deliver content in consumable data file structure for government supply chain risk illumination.

4.12. The contractor shall be able to provide executive summaries, reports, and data visualizations to enable decision making through the use of recognized platforms such as briefings, reports, dynamic dashboards, etc.

4.13. The contractor shall have experience working with unstructured data and conducting research and analysis of open source or publicly available data for commercial organizations.

4.14. The contractor shall provide access to a web-based data analytics platform for the performance of supply chain risk analysis, risk identification and reporting, and continuous monitoring.

4.15. The contractor shall train government personnel and the contract shall immediately provide access to begin utilizing the supply chain illumination platform to conduct supply chain risk analysis on entities identified by the government and notify the department or agencies of all relevant industrial health risk indicators/categories supported by the platform.

4.15.1 The platform shall provide business intelligence analytics that address the following Minimum Risk Indicators /Categories for SCRIPTS Small Business (see Attachment 1);

SCRIPTS Small Business (Set-Aside for Small Business Only)

1. Financial

2. Foreign Ownership Control or Influence (FOCI)

3. Political and Regulatory

4. Compliance

5. Technology and Cybersecurity

The tools should have the ability to expand or adapt as other health risk indicators/categories are prioritized or identified by the government (e.g.Product Quality/Design, Manufacturing and Supply, Transportation and Distribution, Environment). Any additional risk categories above the minimum elements that Small Business tool providers can meet would be viewed more favorably.

Request For Quote 47QCTA24Q0003 PAGE 8

4.15.2 The platform shall provide business intelligence analytics that address the following Minimum Risk Indicators /Categories for SCRIPTS Unrestricted (see Attachment 1);

SCRIPTS Unrestricted - Required Minimum Risk Indicators/Categories:

1. Financial

2. Foreign Ownership Control or Influence (FOCI)

3. Political and Regulatory

4. Compliance

5. Technology and Cybersecurity

6. Manufacturing and Supply

7. Transportation and Distribution

8. Product Quality/Design

Any additional risk categories above the minimum elements that Unrestricted group tool providers can meet would be viewed more favorably.

Additional amplification at the risk sub-category level must include the Minimum Elements to meet identified FAR and program requirements (see Attachment 2).

The platform should have the ability to expand or adapt as other health risk indicators/categories are prioritized or identified by the government (e.g. Product Quality/Design, Manufacturing and Supply, Transportation and Distribution, Environment).

4.16. The contractor shall provide access to the platform for authorized users to run searches on vendors, suppliers, and key personnel based upon defined customer task award quantities and frequency.

4.17. The contractor shall ensure the platform can perform batch uploading of companies, cage codes, UEI, NIINs, etc. and associated personnel/suppliers being screened and vetted for the government.

4.18. The platform must be able to identify companies with any foreign ownership, control, and influence (FOCI) concerns to include: adversarial finance risk indicators, and be able to vet and continuously monitor foreign personnel to identify potential FOCI risk.

4.19. The contractor shall provide access to their supply chain illumination tool database environment, whether through subscription access or cloud-based application services, where applicable, for the term of 12 months. The government will be responsible for renewing subscription-based services access during the defined period of performance. The database environment must also include the ability to access data owned by DoD on any corporate entities, as required.

Request For Quote 47QCTA24Q0003 PAGE 9

4.20. The platform must perform automated language translation in the search process to enable identification of potential foreign risk indicators including foreign ownership, control, and influence.

4.21. The contractor shall provide a program management plan as part of the solicitation. The contractor shall support a contract kick-off meeting with all key stakeholders within 15 days after contract award. The contractor shall provide quarterly status reports for all completed and in-progress actions.

4.22. If required by the ordering agency at the task order level, the contractor shall have the capability to provide appropriately cleared technical data analyst support in secure operating environments, up to TS/SCI environment, to assist with requirements collection, rapid payload development, reporting deliverables, training, and quick-turn RFIs.

4.23. The platform shall support reviews of potential foreign acquirers or investors involved in capital and capability provider applications, and those included in CFIUS cases, as appropriate to government agencies.

4.24. The platform shall provide visualization of an entity centric model that displays an expandable view of holistic supplier, vendor, investor, and key management personnel relationships.

4.25. Continuous Monitoring

4.25.1. The platform shall be able to continuously monitor for risks to supply availability, or production shortages within supply chains with access to all entities in which supply chain risk analysis is requested.

4.25.2. The platform shall establish or provide flagging mechanisms to alert government points of contact to monitoring events on entities as defined by the government.

4.25.3. The contractor shall include support for platform updates and data management, as part of the subscription agreement, as they become available during the period of performance.

4.26. Deliver a Common Operating Picture

4.26.1. The platform shall deliver self-service dashboarding and visualization tools to provide common operating picture, strategic insights, and inform operational decisions on risk trends across all entities.

4.26.2. The contractor shall create an integrated capability to correlate government derived data and Publicly Available Electronic Information (PAEI) data with Cyber Threat Data to visualize and support a common operating picture.

4.26.3. The contractor shall partner with Joint Cyber Intelligence Tool Suite (JCITS) program leads, and associated vendors/systems as identified by the government to integrate all cyber and non-cyber vulnerabilities.

Request For Quote 47QCTA24Q0003 PAGE 10

4.27. Training

4.27.1. The contractor shall develop and execute a detailed training plan for government designated users.

4.27.2. The contractor shall provide web-based training to government designated users, as part of its subscription access, for any aspect of the platform, to include one-on-one and team training events as required and defined at the task order level.

4.28. Risk Illumination of Affiliated Entities and Suppliers

4.28.1. The platform shall provide automated supply chain risk analysis research for corporate network illumination and screening of individuals and businesses affiliated with entities designated by government programs as required based on logic provided by program “IF – THEN” statements. (i.e. If an investor or limited partner is from the Cayman Islands then conduct an additional search to determine Ultimate Beneficial Owner). Government programs will supply clear criteria prior to execution of the task order award.

4.28.2. The platform shall enable development of customizable risk scoring with a learning algorithm that can be tuned by government users to better highlight existing or developing risk.

4.29. Continued configuration / tailoring with new sources and risk events

4.29.1. The contractor should offer new development features (i.e. data sources, risk algorithms, user interface changes) as agreed to in the task order by the contractor and the Government. If required by DoD customer(s), the contractor will collaborate with the government to make the dataset broadly available to DoD customers via the DoD Advanced Analytics (ADVANA) enterprise data catalog.

4.30. FedRAMP Authorization (SaaS offering). The contractor will provide available FedRAMP authorization(s) that have been granted for the platform application or hosted environment in support of ordering agency requirements. If not available, the contractor should submit a FedRAMP Initiation Request, with federal agency sponsorship, as required by the ordering agency, to accelerate insights into potential risks associated with government suppliers. The threshold authorization could be at IL4 or FedRAMP HIGH if supporting Controlled Unclassified Information with an objective threshold of IL6 authorization, if required for use in a government secure operating environment. If required by the ordering agency, the contractor shall ensure that all required authority to operate documentation is also provided.

4.31. General

4.31.1. The contractor shall provide data analyst support, at the ordering agency

Request For Quote 47QCTA24Q0003 PAGE 11 task order level, to optimize AI system performance as defined at the government task order level.

4.31.2. The contractor shall provide configurable out-of-the-box artificial intelligence (AI), Machine Learning (ML) and NLP models that can adapt to the needs and can be tuned to identify network relationships of Key management personnel, supplier and customer relationships and entity resolution to identify ultimate beneficial ownership (UBO). Additionally, the contractor shall incorporate key aspects of Anti- Money Laundering data, including Crypto currency transactions, to identify sources of funds for entities.

4.31.3. The contractor shall provide dedicated SCRM personnel support for the customer for specific programs or organizations, as defined and requested at the task order level. The requested personnel resources will be dedicated to the organization for the level of effort (hours/dollars) contractually agreed upon and may be virtual or onsite.

4.31.3.1. The contractor shall be responsible for promoting the data on corporations specified by the department, service, or agency to ensure data accuracy.

4.31.3.2. The contractor shall be capable of supporting the customer with surge technical support for SCRM data analysis. This includes creating additional detailed reports as specified by the department, service or agency and is specified as a level of effort (hours/dollars) contractually agreed upon for each type of report.

4.31.3.3. The contractor shall support the department, service, or agency in developing and presenting risk data and reports to provide security council and senior leadership insight into the level of risk that the corporations pose to the DoD and Federal agencies.

4.31.4. Commercial entities information that is procured and input into the enterprise level tool (corporate, personnel profiles) from any agency shall be viewable in the defined database environment or otherwise accessible for sharing with other government agencies for that point in time data pull, at no extra cost to the government (“buy once, share everywhere”).

This applies to the corporate and personnel data pulls, as well as to any lower level in depth reports paid for by a government agency. The ability to share this critical Supply Chain Risk information among government agencies requiring government rights in technical data, as described in FAR 52.227-14 for federal agencies and DFARS 252.227-7015 for DoD agencies, is a foundational requirement to support Federal Acquisition Security Council (FASC) strategic objectives, Executive Orders, and Federal/DoD policies.

4.31.5. Annual Report. The contractor shall deliver an Annual Report outlining all accomplished tasks on an annual basis prior to the anniversary of contract award. The report shall be in Microsoft Word electronic format.

4.31.6. Quarterly Program Status Report. The contractor shall deliver quarterly status reports no later than the 10th day of the third month following the previous quarters

Request For Quote 47QCTA24Q0003 PAGE 12 closing. The report shall be in Microsoft Word electronic format.

The quarterly report shall include:

● A statement of the period covered (e.g., calendar month, three month period); The period covered by the report shall correspond to one of more invoices.

● Invoiced activities and deliverables in process and completed

● Status of Cyber Hardening activities

● Schedule /spend plan update

● Meetings and briefings attended

● Project status

● Planned activities for the following month

● Activities funded and date funded

● Cost and fee for the reporting period

4.31.7. Performance Requirements (Notional)

Requirement s

Performance Standards

Acceptable Quality Level

Method of Surveillance

Reporting Reporting is timely, grammatically correct, accurate, and professional in appearance

98% As Reported by Agency PM and recorded by the COR;

Annual Program Review

Contract Management

Ensure all administrative actions are performed within the deadlines set forth by the PWS

100% As Reported by Agency PM and recorded by the COR;

Annual Program Review

Request For Quote 47QCTA24Q0003 PAGE 13

System Tool Training

Ensure new users are trained within 30 days of providing access to the platform.

100% As Reported by Agency PM and recorded by the COR;

Annual Program Review

Platform Availability

Ensure that the platform is accessible to authorized users (e.g. system uptime availability) to support PWS requirements

>98% As Reported by Agency PM and recorded by the COR;

Annual Program Review

5. Period of Performance:

This BPA shall commence on the effective date of contract execution and shall continue in force for a base period of 5 years, with one 5 year option, for a total ordering period of 10 years. The total period of performance of any task award can not exceed ten (10) years.

In accordance with FAR 8.405-3(d)(3), Contractors may be awarded BPAs that extend beyond the current term of their GSA Schedule contract, so long as there are option periods in their GSA Schedule contract that, if exercised, will cover the BPA's period of performance.

Quoters will not be eligible for BPA award if their relevant GSA Schedule contract(s) will expire prior to the end of the BPA’s awarded 10 year period of performance, if no further option periods on the relevant GSA Schedule contract(s) are available. The only exception to this rule is if a quoter has a continuous contract.

The use of a five-year base period and one, five-year option period under this BPA will reduce procurement lead time and associated costs for the option period; ensure continuity of BPA support; improve contractor performance; and facilitate longer-term contractual relationships with the BPA awardee.

Authorized Government Users: The Contractor shall make available/accessible to all authorized users of this BPA the database products and services listed above.

Technology Refreshment / Products and Services Improvement: The Contractor shall offer improvements to the database products and services offered under this BPA as capabilities become commercially available.

Request For Quote 47QCTA24Q0003 PAGE 14

6. Key Personnel Requirements All key personnel assigned to work under this requirement must meet the qualifications in Key Personnel requirements below. Experienced professional and/or technical personnel are essential for successful accomplishment of the work to be performed under this contract. The contractor agrees that such personnel shall not be removed or replaced from the contract work except as follows:

If one or more of the key personnel for whatever reason becomes or is expected to become unavailable for work under this contract for a continuous period exceeding 30 work-days, or is expected to devote substantially less effort to the work than indicated in the proposal, the contractor shall immediately notify the Contracting Officer and shall, subject to the concurrence of the Contracting Officer or their authorized representative, promptly replace such personnel with personnel of at least substantially equal ability and qualifications.

All requests for approval of substitutions or new hires hereunder must be submitted in writing at least 15 days (30 days if security clearance is to be obtained) in advance and provide detailed explanation of the circumstances necessitating the proposed substitutions or new hires to the Contracting Officer. The request must contain a complete resume, along with requisite contact information, for the proposed person(s) and any other information requested by the Contracting Officer to approve or disapprove the proposed substitution. The Contracting Officer or their authorized representative will evaluate such requests and promptly notify the contractor of his approval or disapproval thereof in writing. The contractor agrees that during the first 90 days of the contract performance period no key personnel substitutions will be permitted unless such substitutions are necessitated by an individual's sudden illness, death or termination of employment. In any of these events, the contractor shall promptly notify the Contracting Officer.

All proposed substitutes must meet qualifications as delineated under Personnel Qualifications.

6.1. Personnel Qualification Requirements:

Program Manager

- Must possess a minimum of an advanced degree in a security or business intelligence field of study, or ten years of demonstrated management related work experience.

- Must have recent, within the last three years, hands-on experience in supply chain security intelligence analysis, technology capabilities supporting supply chain risk management and must be a recognized practitioner..

Technical Deployment Manager

- Must possess a minimum of an advanced degree in engineering, computer science or related scientific discipline, or 15 years of related scientific work experience;

- Must be uniquely skilled expert in data analytics or related fields supporting recent capability deployment activities, within the last three years.

7. IT Security Considerations

Request For Quote 47QCTA24Q0003 PAGE 15

Contractors entering into an agreement for service to government activities will be subject to IT security standards, policies, reporting requirements, and governmentwide laws or regulations applicable to the protection of governmentwide information security, Cybersecurity and SCRM are dynamic areas with developing regulations and requirements as evidenced by the ongoing development of the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework by the Department of Defense (DoD), as well as National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, SP800-161, SP 800-171 and SP 800-172. As the SCRIPTS BPA will be a governmentwide acquisition vehicle, with potential customers of both civilian and defense organizations, it is important for the vehicle to remain relevant in light of changing requirements (see Attachment 4, Cybersecurity & Supply Chain Risk Management (SCRM) References).

The theft of intellectual property and Controlled Unclassified Information (CUI) through malicious cyber activity threatens not only the economic security of the United States, but our national security as well. Nation states, criminal and terrorist organizations, and rogue individuals will continue to target the defense industrial base as well as Government agencies and commercial entities in order to disrupt operations and/or undercut our technological advantages.

While CMMC is currently a DoD initiative, it may also have utility as a baseline for civilian acquisitions. SCRIPTS BPA quoters are encouraged to monitor, prepare for and participate in acquiring CMMC certification once CMMC 2.0 standards are promulgated.

Quoters should be aware of developing CMMC 2.0 and SCRM requirements by implementing the appropriate NIST SP 800-series documents, which are foundational to CMMC 2.0, FedRAMP, and other security programs. Once CMMC requirements have been finalized, GSA reserves the right to update the BPA with any applicable FAR clauses and provisions.

Additional cybersecurity and SCRM requirements may be included on individual task orders by the issuing agency OCO. These requirements may vary on individual orders based on the security needs and criticality assessment of the ordering agency.

7.1 Cybersecurity Supply Chain Risk Management Plan

The quoter shall develop and operationally implement a Cybersecurity Supply Chain Risk Management (C-SCRM) plan that addresses system integrity through operational cyber hardening of their commercial infrastructure to ensure resilience against adversarial cyber-attacks within their ecosystem. The plan should be submitted to the government as part of their proposal submission and updated semi-annually, or as mutually agreed upon, to address progress and operational execution against the plan.

7.1.1 The SCRM plan, implementation, and risk assessment methodology processes shall follow Appendix D and E of NIST SP 800-161 Revision 1 (or current revision) (https://csrc.nist.gov/publications/detail/sp/800-161/final) and NISTIR 7622 (https://csrc.nist.gov/publications/detail/nistir/7622/final) guidelines.

Request For Quote 47QCTA24Q0003 PAGE 16

7.1.2 Cybersecurity Supply Chain Risk Management (C-SCRM) Plan Submission To ensure quoters remain aware of and are implementing emerging C-SCRM requirements over the life of the BPA, the SCRIPTS BPA C-SCRM Plan must be submitted to scrmtool@gsa.gov as indicated in PWS Section 9, Deliverables.

GSA will provide a C-SCRM Plan template to contractors prior to the submission dates indicated in PWS Section 9, Deliverables. This template must be utilized for preparation and submission of the required C-SCRM Plan. The C-SCRM Plan template may be updated by GSA throughout contract performance to reflect current SCRM factors and authoritative guidance. The C-SCRM Plan template may include, but will not limited to the following sections and will identify additional risk factor elements within Section 11 identified below:

1. Cover Page 2.Table of Contents

3. C-SCRM Plan Approval

4. System Name and Identifier

5. System Description

6. System Information Type and Categorization

7. System Operational Status

8. Role Identification

9. System/Network Diagrams, Inventory and Life Cycle Activities

10. Information Exchange and System Connections

11. Security Control Details (Minimum Control Baseline)

12. Contingencies and Emergencies

13. Revision and Maintenance

14. Acronym List

15. Terms and Definitions

16. References

17. Attachments

18. Related Laws, Regulations and Policies

19. C-SCRM Activities and Life Cycles

In the event GSA identifies necessary revisions to the submitted C-SCRM plan, a revised plan must be resubmitted within 30 days of notice from GSA. Failure to resolve any identified deficiencies in a timely manner may result in Government action, up to and including contract termination.

7.1.3 Risk Assessment

The Government may identify, assess, and monitor contractors’ supply chain risks in connection with product and service offerings. The Government may use any information from public unclassified, classified, or any other sources for its analysis. Once complete, the Contractor agrees the Government may, at its own discretion, perform audits of supply chain risk processes or events. On-site assessments may be required. GSA may monitor the following supply chain risks:

Request For Quote 47QCTA24Q0003 PAGE 17

1. Risk of Foreign ownership, control, or influence

2. Cyber threats

3. Other supply chain risks which could impact the company’s vulnerability, such as financial performance issues In the event supply chain risks are identified and corrective action becomes necessary, mutually agreeable corrective actions will be sought based upon specific identified risks. Failure to resolve any identified risk in a timely manner may result in Government action, up to and including contract termination.

7.2 Security: Facility Clearance Level (FCL)

If required by the Agency customer task order, the quoter must be capable of supporting customer task order requirements, up to and including Top-Secret/SCI. If defined by the ordering activity during the RFQ stage of the procurement, the quoter shall provide the necessary Facility Clearance Level (FCL) documentation (e.g. DD441 or agency equivalent) at the time of proposal submission and maintain it in accordance with National Industrial Security Program Operating Manual (NISPOM) to perform classified work throughout the duration of the effort.

Verification of the FCL will be accomplished by GSA contacting the Defense CounterIntelligence and Security Agency (DCSA).

The government anticipates that the contractor could require access to classified information up to and including Secret/Top Secret/TS-SCI during the period of performance. If the prime contractor does not hold the appropriate FCL to support this activity, the government agency may sponsor the prime contractor’s request for an FCL, which must be submitted within 60 (as appropriated based on when classified access is anticipated) calendar days of contract award. No classified access will be granted by the government until the FCL requirement has been satisfied.

Based upon the lengthy process involved in obtaining an FCL, and the possibility of a negative outcome that would render the contractor unable to perform, the impact of not having an FCL could make the agency vulnerable to delays in performance. The SCRIPTS BPA program will not sponsor facility security clearances.

7.3 Security: Personnel Clearances

The quoter is responsible for providing personnel with appropriate security clearances to ensure compliance with Government security regulations, as specified in the ordering agency task order.

The quoter must fully cooperate on all security checks and investigations by furnishing requested information to verify the quoter employee's trustworthiness and suitability for the position.

Clearances may require Special Background Investigations (SBI), Sensitive Compartmented Information (SCI) access or Special Access Programs (SAP), or agency-specific access, such as a Q clearance or clearance for restricted data. Quoters should refer to task order solicitations for guidance on whether or not the customer agency will pay for the investigation or if the quoter is responsible for the cost of the investigation. The SCRIPTS BPA program will not sponsor personnel clearances.

8. Contract Administration

8.1. Place of Performance:

Request For Quote 47QCTA24Q0003 PAGE 18

The primary place of performance will be at the contractor’s work site. If required at the task order level, the customer may define alternate work locations as either onsite government customer location, or remote operating location.

8.2. Travel: N/A

8.3. Contracting Officer’s Representative (COR):

An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor if that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract. The Contracting Officer’s Representative will be appointed at the time of BPA award.

Ordering Agencies will perform all COR responsibilities for any resulting task order(s). The ordering level agency will have a TPOC for any awarded task order(s). The COR responsibilities will be described in a COR Letter of Appointment provided by the ordering agency. The order level COR and TPOC will be responsible for quality assurance surveillance.

Inspection and acceptance of all work performance, reports, and other deliverables under any will be performed by an individual appointed at the ordering level. The COR/TPOC at the agency level will be responsible for identifying where inspection and acceptance will occur.

8.4 Category Management Reporting:

During the PoP of this BPA it is projected that Transactional Data Reporting (TDR) will become a GSA MAS requirement. At that time, the Contractor must register in the government designated system in order to report transactional data in accordance with GSAR 552.216-75 deviation dated June 2022.

The contractor must provide the requested sales reporting data, outlined in Attachment 3, Category Management Reporting, electronically via the government designated system. The Contractor must adhere to the instruction and definitions for each reported data element as stated within the government designated system web page. The Government intends to post the reported hourly labor rates to the Prices Paid portal. The Prices Paid portal will be made available to Ordering Contracting Officers and agency program staff via a separate secured Government portal. Submitted data may be provided to BPA customers, upon request, to the extent permitted by Law. The reporting of sales reporting data is required for the following items, within the date specified in Section 9:

● Task Order Award

● Modification

● Invoices

● Zero Invoice (if applicable, when no invoice is shown for an active order month)

Request For Quote 47QCTA24Q0003 PAGE 19

Data quality is significantly important; therefore, GSA may request from the Contractors corrections to the government designated system data, if applicable. Contractors must correct the government designated system data within the date specified below in Section 9, Deliverables.

8.5 Small Business Plan (Unrestricted Awards)

Quoters are to submit their most recent GSA Multiple Award Schedule contract electronic Subcontracting Reporting System (eSRS) signed report with their quote submission. Submission of this documentation should be labeled/saved as Company Name eSRS Report (i.e. “ABC Inc eSRS Report”). Reports are required for each large business CTA team member. Quoters will be rated more favorably if their most recent GSA Multiple Award Schedule contract Individual eSRS report reflects that they have met or exceeded their small business subcontracting goals percentage (reference 2a. of the Quoters Multiple Award Schedule) subcontracting report for individual contracts. For CTA teams, this means that each large business CTA team member must have met or exceeded their GSA Multiple Award Schedule contract small business subcontracting goals percentage in order to receive the favorable rating.

8.6 Integrated Quality Management System (IQMS)

The contractor should follow current International Organization for Standardization (ISO) 9001:2015 certification for services related…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .